首页> 外文会议>Systems Engineering: Shining Light on the Tough Issues >Certification Accreditation – The Role of SecurityEngineering in the Systems Development Life Cycle
【24h】

Certification Accreditation – The Role of SecurityEngineering in the Systems Development Life Cycle

机译:认证与鉴定– SecurityEngineering在系统开发生命周期中的作用

获取原文
获取原文并翻译 | 示例

摘要

Security is most effective if it is planned and managed throughout an organizationsrnSystems Development Life Cycle (SDLC). Many security risks, analyses, and eventsrnoccur during a systems or applications lifetime and these issues should be dealt with fromrnthe initial planning stages and continue through all phases of the SDLC. Many systemsrntoday must also address Certification and Accreditation (C&A) before going operational.rnC&A facilitates including security as an element of the SDLC assuring that a clear set ofrnSecurity Requirements is developed and implemented, residual risk is minimized andrnclearly understood, and all security controls developed and deployed in the finalrnoperational system are documented in a System Security Plan. This paper examines thernrole of security engineering and their activities throughout the SDLC and the C&Arnprocess, the guidance that helps define the Security Requirements, and the roles of thernpeople involved to provide a basic understanding of security engineering as it applies tornC&A throughout the SDLC. One of the objectives of this paper is to help ProgramrnManager’s understand and take into account the C&A process into program plans andrnschedules.
机译:如果在整个组织的系统开发生命周期(SDLC)中进行计划和管理,安全性将是最有效的。在系统或应用程序生命周期中会发生许多安全风险,分析和事件,这些问题应从最初的计划阶段开始处理,并持续到SDLC的所有阶段。如今,许多系统在投入运行之前还必须解决认证和鉴定(C&A)问题。C&A有助于将安全性作为SDLC的组成部分,以确保制定并实施了一套清晰的安全性要求,将残留风险降至最低并得到了清晰理解,并开发了所有安全控制措施。部署在最终运行系统中的文件记录在系统安全计划中。本文研究了整个SDLC和C&Arnprocess中安全工程的作用及其活动,有助于定义安全要求的指南以及所涉及人员的角色,以提供对安全工程的基本了解,因为它适用于整个SDLC中的C&A。本文的目的之一是帮助ProgramrnManager了解并考虑将C&A流程纳入计划计划和时间表中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号